ForgeApply
Try it free

ForgeApply · Job listing

Director of Cybersecurity Governance, Risk and Compliance

The University of Texas at Austin

UT MAIN CAMPUS, USonsite

See all 384 open roles at The University of Texas at Austin

Tailor your resume for this The University of Texas at Austin job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for The University of Texas at Austin's site. Free trial, no card required.

About this role

Job Posting Title: Director of Cybersecurity Governance, Risk and Compliance ---- Hiring Department: Dell Medical School ---- Position Open To: All Applicants ---- Weekly Scheduled Hours: 40 ---- FLSA Status: Exempt from FLSA ---- Earliest Start Date: Immediately ---- Position Duration: Expected to Continue ---- Location: UT MAIN CAMPUS ---- Job Details: General Notes The Director of Cybersecurity Governance, Risk and Compliance leads the information security Governance, Risk and Compliance (GRC) program for UT Medicine and Dell Medical School. Reporting to the Deputy CISO, this role builds and operates a mature GRC function that enables the organization to assess, manage, and mitigate cybersecurity risk across a clinical, academic, and research environment on a path toward full hospital operations in 2030.

Dell Medical School operates within UT Austin’s established enterprise security program, inheriting a baseline of policies, procedures, and tooling. This allows Dell Medical School’s cybersecurity governance program to focus on areas of risk specific to its clinical and research mission. Rather than rebuilding foundational controls, this role concentrates on assessing risk and developing security policies, standards, and procedures specific to healthcare delivery, clinical research, and regulatory compliance.

Beyond GRC, this role owns Dell Medical School’s incident response coordination capability for events that exceed UT Austin’s initial response scope, including driving communication, escalation, and decision-making across clinical and business stakeholders through resolution. This includes maintaining business continuity and disaster recovery plans for clinical and business systems where Dell Medical School bears primary responsibility.

Purpose The Director of Cybersecurity Governance, Risk and Compliance provides strategic leadership for Dell Medical School’s information security governance, risk management, and compliance program. This position develops and executes GRC strategy, evaluates cybersecurity risk, establishes healthcare- and research-specific security governance, oversees regulatory compliance, and provides executive-level reporting on organizational risk posture and program maturity.

Operating within UT Austin’s federated security environment, the Director partners with technology, clinical, research, legal, privacy, audit, and compliance stakeholders to manage cybersecurity risk while supporting Dell Medical School’s continued growth toward full hospital operations. The role also provides leadership for third-party risk management, incident response coordination, business continuity and disaster recovery, research security governance, and application security governance.

Responsibilities GRC Program Leadership and Strategy • Develop and execute the Dell Medical School GRC strategy aligned with organizational objectives, regulatory requirements, and the 2030 hospital opening. • Build and lead a team of GRC analysts and security compliance professionals, providing ongoing coaching and career development. • Deliver executive-level reporting on risk posture, compliance status, and program maturity to the Deputy CISO and governance bodies. • Develop a GRC metrics and KPI framework measuring program effectiveness, employee compliance behavior, and security posture improvement over time. • Evaluate cybersecurity insurance options and risk-transfer mechanisms as part of the organization’s residual risk strategy. • Coordinate with internal audit, legal, privacy, and enterprise compliance to align governance activities and manage risk consistently across organizational units.

Risk Assessment and Security Posture • Lead the annual HIPAA Security Risk Analysis and coordinate remediation planning with technology and operational leaders. • Conduct security risk assessments of infrastructure solutions and clinical platforms to evaluate control adequacy and identify gaps. • Maintain a risk register and hold technology and operational leaders accountable to remediation timelines across the clinical, academic, research, and administrative technology portfolio. • Perform business impact analysis to evaluate the effect of cybersecurity risks on critical clinical operations and business functions. • Evaluate the cost-effectiveness of security controls through structured cost-benefit analysis to optimize risk reduction relative to available resources. • Conduct cyber risk trend analysis and reporting to identify emerging threats and inform remediation priorities. • Execute security authorization reviews for new system acquisitions and major system changes, with authority to withhold security authorization until risks are reduced to acceptable thresholds.

Governance, Policy and Compliance • Author and maintain Dell Medical School cybersecurity policies, including policies that are more stringent than UT Austin baseline requirements where HIPAA, clinical operations, or research compliance demands. • Ensure Dell Medical School security policies comply with applicable federal and state regulations and operate within the UT Austin enterprise security charter. • Leverage applicable UT Austin security standards and guidelines and develop Dell Medical School-specific standards for clinical, biomedical, and clinical trial environments. • Retain ownership of Dell Medical School security processes and procedures across operational domains. • Identify top human cybersecurity risks and design behavioral mitigation campaigns targeting clinical, research, and administrative staff populations. • Design and deliver a security awareness program using adult learning principles and maintain metrics to measure employee behavior change and program effectiveness. • Respond to regulatory inquiries and support external audit engagements in coordination with Legal and Privacy while maintaining comprehensive compliance documentation.

Third-Party and Vendor Risk Management • Develop and operate a vendor s

Tailor your resume for this The University of Texas at Austin role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Browse all jobs

Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview